CVE-2002-0644

Microsoft SQL Server and MSDE 2000 - Buffer Overflow in Database Consistency Checker

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-0644. PoCs published by Cesar Cerrudo.

AI-analyzed exploit summary This exploit leverages a buffer overflow in Microsoft SQL Server 2000's DBCC utilities to execute arbitrary commands via the `sp_MScopyscriptfile` stored procedure, allowing an attacker to write and execute commands on the target system.

Description

Buffer overflow in several Database Consistency Checkers (DBCCs) for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows members of the db_owner and db_ddladmin roles to execute arbitrary code.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Cesar Cerrudo · textremotewindows
https://www.exploit-db.com/exploits/21650

This exploit leverages a buffer overflow in Microsoft SQL Server 2000's DBCC utilities to execute arbitrary commands via the `sp_MScopyscriptfile` stored procedure, allowing an attacker to write and execute commands on the target system.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft SQL Server 2000
Auth required
Prerequisites: Access to a vulnerable Microsoft SQL Server 2000 instance · Sufficient privileges to execute stored procedures
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

EPSS 0.1142
EPSS Percentile 95.4%

Details

Status published
Products (2)
microsoft/data_engine 2000
microsoft/sql_server 2000
Published Aug 12, 2002
Tracked Since Feb 18, 2026